nextjs-supabase-auth
Pass
Audited by Gen Agent Trust Hub on Sep 26, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides comprehensive security guidance, specifically warning against insecure authentication methods such as
getSession()in favor of the more securegetUser(), which involves server-side validation. - [SAFE]: Includes a structured reference system (
validations.md,sharp_edges.md) designed to audit and correct common implementation errors, demonstrating a defensive security posture. - [SAFE]: Environment variable usage for Supabase configuration (
NEXT_PUBLIC_SUPABASE_URL,NEXT_PUBLIC_SUPABASE_ANON_KEY) follows standard security practices for public keys in client-side frameworks. - [SAFE]: Dependency on
@supabase/ssrrefers to an official, well-known library for Supabase integration, posing no supply chain risk.
Audit Metadata